Cross-chain infrastructure suffered another serious blow this week as Wanchain confirmed that approximately 515 million NIGHT tokens were drained from the treasury of its Cardano-BNB Chain bridge in a series of unauthorized transactions. The team has since disabled the bridge entirely while it investigates what appears to be a cryptographic signature flaw at the heart of the exploit. With cross-chain bridges repeatedly proving to be among the most fragile points in decentralized infrastructure, the incident raises urgent questions about signature verification standards and the treasury custody models that bridge protocols rely upon.

What Happened

According to Wanchain's public confirmation, the NIGHT tokens — held in the bridge's treasury to facilitate cross-chain transfers between Cardano and BNB Chain — were removed through a sequence of transactions that the team characterized as unauthorized. The suspected mechanism is a signature flaw: a vulnerability in the cryptographic signing process that governs whether a withdrawal from the bridge treasury is considered legitimate. If a signature scheme can be manipulated or forged, it effectively hands an attacker the keys to the treasury without requiring access to private keys in the conventional sense. Wanchain stated it would release a fuller post-mortem once its internal review is complete, but the bridge itself remains offline pending those findings.

The Signature Problem in Cross-Chain Bridges

Signature vulnerabilities represent one of the most technically treacherous categories of smart contract exploits. Unlike a straightforward reentrancy attack or an oracle manipulation, a flawed signature scheme can be invisible in routine audits if the verifier logic contains subtle edge cases — malformed inputs, hash collisions, replay vectors, or weak threshold conditions in multi-signature setups. Cross-chain bridges are particularly exposed because they sit at the intersection of two or more independent execution environments, each with its own cryptographic primitives. Mapping Cardano's extended Unspent Transaction Output (eUTXO) model against BNB Chain's account-based Ethereum Virtual Machine (EVM) architecture introduces non-trivial translation risks at the signature layer. A discrepancy in how one chain interprets a signed message versus another can create an opening that a sophisticated attacker can widen into a full treasury drain.

The scale of this specific incident — 515 million NIGHT tokens extracted in what appears to be a coordinated series of transactions rather than a single withdrawal — suggests the attacker, or attackers, had a detailed understanding of the bridge's transaction flow and limits. Repeat withdrawals of this nature typically indicate either automated exploitation scripts or deliberate batching designed to stay beneath detection thresholds long enough to clear the bulk of the funds.

Bridges Keep Bleeding

The Wanchain incident lands in an already crowded graveyard of bridge exploits. The sector has endured some of the largest individual thefts in blockchain history, from the Ronin Network's $625 million compromise to the $320 million Wormhole hack, to Nomad's $190 million drain. What connects many of these incidents is not brute-force attacks on consensus mechanisms but rather precision strikes on the logic layers that validate cross-chain messages and authorize fund releases. Treasury custody — the model by which locked assets are held and released — remains the Achilles' heel. Bridges are, by structural necessity, custodians of large concentrated pools of value, and any flaw in the authorization layer transforms that concentration into a single point of catastrophic failure.

Wanchain has positioned itself over the years as a serious interoperability infrastructure provider, operating bridges across a range of blockchain ecosystems. The fact that this exploit targeted its Cardano integration specifically is notable. Cardano's relatively smaller DeFi ecosystem means fewer bridges serve it compared to Ethereum or Solana, which in turn means fewer independent security eyes scrutinizing those connections in real time. Lower liquidity bridges can paradoxically attract targeted attacks precisely because their treasury balances may sit large relative to the on-chain monitoring activity around them.

What Comes Next

Wanchain has committed to releasing further details once its internal investigation wraps up, a standard but important step. The quality of that post-mortem will matter enormously — not just for affected NIGHT token holders who need to understand the scope of their exposure, but for the wider bridge security community that depends on transparent incident disclosures to harden its own systems. Whether the protocol can recover operationally, and under what conditions it reopens the Cardano-BNB Chain bridge, will depend heavily on whether the root cause can be conclusively identified and patched rather than merely patched around.

For the NIGHT token community specifically, the immediate concern is the disposition of the drained tokens. Whether the attacker can liquidate 515 million tokens without catastrophic market impact, and whether Wanchain has any recovery mechanism or insurance fund in place, remain open questions the post-mortem must address. Until then, the bridge stays dark — another piece of cross-chain infrastructure taken offline by a vulnerability that, in retrospect, should have been the first thing auditors stress-tested.

Written by the editorial team — independent journalism powered by Bitcoin News.